CVE-2023-53936
Cameleon CMS 2.7.4 Authenticated Persistent Cross-Site Scripting via Post Creation
Cameleon CMS 2.7.4 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts into post titles. Attackers can create posts with embedded SVG scripts that execute when other users mouse over the post title, potentially stealing session cookies and executing arbitrary JavaScript.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Affected products
tuzitio · Cameleon CMSWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →